CVE-2024-29010

HIGH

SonicWall GMS <= 9.3.4 - XML External Entity Injection via ECM URL Endpoint

Title source: llm
STIX 2.1

Description

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0062
EPSS Percentile 44.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
SonicWall/GMS 9.3.4 and earlier versions
Published May 01, 2024
Tracked Since Feb 18, 2026